Lesson 17 / 28
Per-User Authorisation and Audit Logging
Run tools as the user, not as a super-account, and record every decision.
Confused deputy and evidence
If the assistant uses one powerful service account for every user, then user A can ask it to fetch user B's data, and the assistant, a confused deputy, will happily comply. Pass the end user's identity and permissions down to every tool (use delegated tokens scoped to that user, or enforce checks with the user's ID in the data layer) so the tool can only do what the user could do directly. Alongside, keep an audit log: who asked, which tool, which arguments (with secrets and personal data redacted), the policy decision, the approver and the outcome. Audit logs support incident response, show whether approvals work and reveal attempted abuse patterns. Protect the logs themselves from tampering and from becoming a new data leak.
Structured audit events with redaction, run
I ran this with plain Python 3 (standard library only). All attacks here are harmless demonstrations on local data, using no real systems. Each tool call becomes a JSON event with user, tool, arguments and the policy decision. A token that appeared in an argument is replaced by [REDACTED] before logging.
import json, re
KEY = re.compile(r"sk-[A-Za-z0-9_-]{8,}")
def audit_event(user, tool, args, decision):
safe_args = {k: (KEY.sub("[REDACTED]", v) if isinstance(v, str) else v) for k, v in args.items()}
return json.dumps({"user": user, "tool": tool, "args": safe_args, "decision": decision}, sort_keys=True)
print(audit_event("asha", "send_email", {"to": "ravi@example.com", "note": "token sk-live-abc12345 attached"}, "ASK"))
print(audit_event("asha", "refund", {"order": "481516", "amount": 300}, "ALLOW"))
Output:
{"args": {"note": "token [REDACTED] attached", "to": "ravi@example.com"}, "decision": "ASK", "tool": "send_email", "user": "asha"}
{"args": {"amount": 300, "order": "481516"}, "decision": "ALLOW", "tool": "refund", "user": "asha"}Protect the logs too
Audit logs contain sensitive details. Restrict access and set retention limits.
Quick check: What is a "confused deputy" in an LLM app?
- A missing comma
- A slow model
- A privileged assistant tricked into doing something the requesting user is not allowed to do
- A type of GPU
Answer
A privileged assistant tricked into doing something the requesting user is not allowed to do — Authorise as the end user so the assistant cannot exceed the user's rights.